<?php 
include '../data/data.php';
include '../data/ip.php';
$user=$_SESSION['user']; //获取到的用户名
$pass=$_SESSION['pass']; //获取到的密码
$type=$_POST['type']; // 1 2 3 4
$date=date("Y-m-d");  //时间
$result= mysql_query("SELECT * FROM user WHERE username='$user' and password='$pass'", $link);  
$row = mysql_fetch_array($result);
if($row[id]==''){
	header('location:/user/login.html?fwd=/user/shop.html');
}
if($_SERVER['REQUEST_URI']!='/pay/shop' & $_SERVER['REQUEST_URI']=='/pay/shop.php'){
	exit('<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /pay/cdk.html was not found on this server.</p>
<hr>
<address>Apache Server at www.81im.com Port 80</address>

</body></html>');
}
if($type==''){
exit('<html><head>
<title>404 Not Found</title>
</head><body>
<h1>Not Found</h1>
<p>The requested URL /pay/cdk.html was not found on this server.</p>
<hr>
<address>Apache Server at www.81im.com Port 80</address>

</body></html>');
}
if($type=='1'){
  $shop='88';
  if($row[jifen]>$shop||$row[jifen]==$shop){
$resulty= mysql_query("UPDATE user SET jifen=jifen-'$shop' WHERE username='$user'", $link); 
      if($resulty){
        $datex=date("Y-m-d H:i:s");
      mysql_query("INSERT INTO shop (userid, user, money, type, date) VALUES ('$dl', '$user', '$shop', '$type', '$datex')", $link);  
        $returndata = array("errcode"=>1,"info"=>"success");
         exit(json_encode($returndata));
      }
  }else{
  $returndata = array("errcode"=>1,"info"=>"您的积分不足无法提交！");
    exit(json_encode($returndata));
  }

}elseif($type=='2'){
  $shop='130';
  if($row[jifen]>$shop||$row[jifen]==$shop){
$resulty= mysql_query("UPDATE user SET jifen=jifen-'$shop' WHERE username='$user'", $link); 
      if($resulty){
        $datex=date("Y-m-d H:i:s");
      mysql_query("INSERT INTO shop (userid, user, money, type, date) VALUES ('$dl', '$user', '$shop', '$type', '$datex')", $link);  
        $returndata = array("errcode"=>1,"info"=>"success");
         exit(json_encode($returndata));
      }
  }else{
  $returndata = array("errcode"=>1,"info"=>"您的积分不足无法提交！");
    exit(json_encode($returndata));
  }

}elseif($type=='3'){
  $shop='220';
  if($row[jifen]>$shop||$row[jifen]==$shop){
$resulty= mysql_query("UPDATE user SET jifen=jifen-'$shop' WHERE username='$user'", $link); 
      if($resulty){
        $datex=date("Y-m-d H:i:s");
      mysql_query("INSERT INTO shop (userid, user, money, type, date) VALUES ('$dl', '$user', '$shop', '$type', '$datex')", $link);  
        $returndata = array("errcode"=>1,"info"=>"success");
         exit(json_encode($returndata));
      }
  }else{
  $returndata = array("errcode"=>1,"info"=>"您的积分不足无法提交！");
    exit(json_encode($returndata));
  }

}elseif($type=='4'){
  $shop='200';
  if($row[jifen]>$shop||$row[jifen]==$shop){
$resulty= mysql_query("UPDATE user SET jifen=jifen-'$shop' WHERE username='$user'", $link); 
      if($resulty){
        $datex=date("Y-m-d H:i:s");
      mysql_query("INSERT INTO shop (userid, user, money, type, date) VALUES ('$dl', '$user', '$shop', '$type', '$datex')", $link);  
        $returndata = array("errcode"=>1,"info"=>"success");
         exit(json_encode($returndata));
      }
  }else{
  $returndata = array("errcode"=>1,"info"=>"您的积分不足无法提交！");
    exit(json_encode($returndata));
  }

}
